Contextual Malware Detection via System Activity Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware detection methods rely on reactive signature-based approaches that fail to identify malicious software when it undergoes superficial changes, allowing it to evade detection, as they only work when the software is determined to be malicious ahead of time.
Innovation Solution
A system that uses contextual information, such as recent system activity, infection history, and geographic location, combined with traditional detection methods and machine learning techniques, to determine if a software application is malicious, enabling proactive detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If signature-based detection is used, then detection speed is improved, but detection accuracy deteriorates when malware is modified
Solution Approach 1:
The system performs preliminary analysis of system state and contextual information before making a detection decision. By examining infection history, recent system changes, and behavioral patterns in advance, the system builds a contextual profile that enhances detection accuracy without sacrificing the speed of signature-based matching.
Solution Approach 2:
The patent introduces contextual information as an intermediary layer between signature matching and final detection decisions. This intermediary layer analyzes system state, infection history, and behavioral patterns to validate or supplement signature-based detections, thereby improving accuracy while maintaining the rapid response capability of traditional methods.
2Ease of manufacture
If reactive detection approach is used, then implementation simplicity is improved, but detection capability deteriorates for modified malware
Solution Approach 1:
The system transitions from a static signature-based approach to a dynamic detection framework that continuously monitors and adapts to system state changes. By incorporating real-time contextual information about system behavior, infection history, and environmental factors, the system maintains simplicity while significantly improving its ability to detect modified malware variants.
Solution Approach 2:
The patent implements feedback mechanisms where detection results, system state changes, and contextual information are continuously analyzed and fed back into the detection process. This feedback loop enables the system to learn from past infections and system behaviors, improving its capability to detect modified malware while maintaining an straightforward implementation through rule-based contextual analysis.
3Use of energy by moving object
If traditional fingerprinting is used, then computational efficiency is improved, but adaptability deteriorates when malware changes
Solution Approach 1:
The system adds another dimension to traditional fingerprinting by incorporating contextual information from multiple sources including system state, infection history, and behavioral patterns. This multi-dimensional approach allows the system to maintain the computational efficiency of traditional hashing while gaining adaptability to modified malware through contextual analysis of the extended feature space.
Data Source
AI summary
Novel methods, components, and systems that enhance traditional techniques for detecting malicious software are presented. More specifically, we describe methods, components, and systems that leverage important contextual information from a client system (such as recent history of events on that system) to detect malicious software that might have otherwise gone ignored. The disclosed invention provides a significant improvement with regard to detection capabilities compared to previous approaches.


